The record
Written from the 1 report below. Nothing here is unsourced.
- Attackers are actively exploiting a critical vulnerability in the Issabel Framework that lets them run operating system commands without needing any login.
- The flaw, tracked as CVE-2026-89026, stems from a hard-coded JWT signing key that is identical across every installation, allowing attackers to forge valid tokens.
- Attackers can use the forged token to trigger Asterisk to execute arbitrary commands as the Asterisk user.
- A patch was released on August 1, 2026, replacing the hard-coded key with one stored in a configuration file, and exploitation was first observed on September 9, 2026.
- The flaw carries a severity score of 9.8, so Issabel Framework users should apply the latest fixes to stay protected.
What to watch next
- Details on who is behind the attacks and the scale of exploitation
- Whether exploitation spreads to more Issabel installations running unpatched versions
Coverage1
1 report
English national1
All filed from India
Named India · Asterisk · Issabel Framework · Shadowserver Foundation · VulnCheck
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
